RANSOMWARE VICTIMTECHNOLOGYDUPLICATE CLAIM

h2o.ai

h2o.ai
linkc📍 United States (US)📅 January 29, 2025
5
same group

Attack Intelligence

h2o.ai was compromised in a ransomware attack attributed to linkc in January 2025. The organization, operating in the Technology sector in United States, was added to the group's data leak site as part of an extortion campaign.

linkc operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

As a result of our operation, we have discovered the following concerning data: 1. Unanonymized customer datasets intended for AI training. 2. Full source code of programs from the Git repository, including code for driverless systems, GPT models, and others. 3. A substantial amount of internal information, including contracts, customer personal data, project costs, and project documentation. 4. Backup copies of employee email accounts containing customer correspondence.

Other Victims — linkc (5)

Quick Facts

CountryUnited States (US)
SectorTechnology
Attack DateJan 29, 2025
Domainh2o.ai
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

linkc
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.